•  
      request #42221 golang.org/x/net bump to 0.37.0
    Infos
    #42221
    Martin GOYOT (goyotm)
    2025-03-13 16:49
    2025-03-13 16:04
    43889
    Details
    golang.org/x/net bump to 0.37.0

    Fixes CVE-2025-22870. See https://pkg.go.dev/vuln/GO-2025-3503

    golang.org/x/net/proxy is used in:

    • pre-receive-tuleap-git-repo-validation
    • vault-tuleap-plugin

    golang.org/x/net/http/httpproxy is used in:

    • tuleap-smokescreen
    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Martin GOYOT (goyotm)
    Closed
    2025-03-13
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-03-13 16:12

    No security impact, impacted code is only called in Smokescreen for which we never set proxy patterns.


    • Reported in version set to All